Sploitus

CVE-2021-44657

No indexed exploits for CVE-2021-44657 yet

In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.

Affected products
Stackstorm, Jinja
Stackstorm
< 3.6.0
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
2.5% (83th percentile)
NVD status
Modified
Published
2021-12-15
CVE-2021-44657 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2021-44657 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2021-44657 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.